CVE-2026-10520
CRITICAL KEV NUCLEIIvanti Sentry - Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
Title source: ruleExploitation Summary
CVE-2026-10520 is actively exploited and listed in the CISA Known Exploited Vulnerabilities (KEV) catalog, added June 11, 2026. EIP tracks 10 public exploits from researchers including SecureWithUmer, HORKimhab, emilliewatson96. A Nuclei detection template is also available.
AI-analyzed exploit summary The repository claims to be a PoC for CVE-2026-10520, an unauthenticated OS command injection vulnerability in Ivanti Sentry. However, the provided Python script only prints a banner and redirects users to an external GitLab link, containing no functional exploit code or technical implementation details.
Description
An OS Command Injection vulnerability in Ivanti Sentry before the R10.5.2, R10.6.2 and R10.7.1 versions allows a remote unauthenticated user to achieve root-level remote code execution
Exploits (10)
The repository claims to be a PoC for CVE-2026-10520, an unauthenticated OS command injection vulnerability in Ivanti Sentry. However, the provided Python script only prints a banner and redirects users to an external GitLab link, containing no functional exploit code or technical implementation details.
This repository contains no actual exploit code or technical analysis for CVE-2026-10520. It only lists external links to other repositories and an encrypted backup file hosted on an archive service, which is a common social engineering tactic to lure researchers into downloading untrusted content.
The repository contains a functional mass scanner/exploit for CVE-2026-10520, targeting Ivanti Sentry's pre-auth RCE vulnerability. It uses async I/O to efficiently check multiple targets by sending crafted POST requests to '/mics/api/v2/sentry/mics-config/handleMessage' and parsing responses for command execution output.
The repository contains only a minimal README with a CVE title and no exploit code, technical details, or functional content. It appears to be a placeholder or stub.
The repository claims to contain a PoC for CVE-2026-10520 but only provides a placeholder script that redirects users to an external GitLab link. No actual exploit code is included.
This repository contains a functional exploit for CVE-2026-10520, an unauthenticated OS command injection vulnerability in Ivanti Sentry. The exploit sends crafted XML payloads to the MICS API endpoint to execute arbitrary commands as root.
The repository contains a functional Python exploit for CVE-2026-10520, targeting Ivanti Sentry. The exploit demonstrates pre-authentication remote code execution (RCE) by sending a crafted HTTP POST request to the '/mics/api/v2/sentry/mics-config/handleMessage' endpoint, allowing arbitrary command execution as root.
The repository contains two Python scripts designed to detect CVE-2026-10520, an Ivanti Sentry command execution vulnerability. The scripts send crafted POST requests to the vulnerable endpoint and analyze responses for vulnerability markers, but do not include exploit payloads for actual command execution.
This repository contains a Python-based scanner for detecting CVE-2026-10520, an OS command injection vulnerability in Ivanti Sentry. The tool sends crafted HTTP requests to the target endpoint and checks for specific response patterns to determine vulnerability status.
This repository contains a functional Python script that exploits CVE-2026-10520 and CVE-2026-10523 in Ivanti Sentry, demonstrating authentication bypass and remote code execution via a crafted API request to the `/mics/api/v2/sentry/mics-config/handleMessage` endpoint.
Nuclei Templates (1)
html:"Ivanti" html:"Sentry"
References (3)
Scores
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H